Merge pull request #8 from volatilityfoundation/mhl-cmhive

move the hive name decision to _CMHIVE extension for hivelist (and ot…
This commit is contained in:
ikelos
2017-07-19 20:43:05 +01:00
committed by GitHub
3 changed files with 17 additions and 7 deletions
@@ -14,6 +14,7 @@ class WindowsKernelIntermedSymbols(intermed.IntermediateSymbolTable):
self.set_type_class('_LIST_ENTRY', extensions._LIST_ENTRY)
self.set_type_class('_EPROCESS', extensions._EPROCESS)
self.set_type_class('_UNICODE_STRING', extensions._UNICODE_STRING)
self.set_type_class('_CMHIVE', extensions._CMHIVE)
@classmethod
def get_requirements(cls):
@@ -4,7 +4,7 @@ import string
from volatility.framework import interfaces
from volatility.framework import objects
from volatility.framework import exceptions
# Keep these in a basic module, to prevent import cycles when symbol providers require them
@@ -13,6 +13,20 @@ class _ETHREAD(objects.Struct):
"""Return the EPROCESS that owns this thread"""
return self.ThreadsProcess.dereference(kernel_layer)
class _CMHIVE(objects.Struct):
@property
def name(self):
"""Determine a name for the hive. Note that some attributes are
unpredictably blank across different OS versions while others are populated,
so we check all possibilities and take the first one that's not empty"""
for attr in ["FileFullPath", "FileUserName", "HiveRootPath"]:
try:
return getattr(self, attr).String
except (AttributeError, exceptions.InvalidAddressException):
pass
return None
class _UNICODE_STRING(objects.Struct):
@property
+1 -6
View File
@@ -21,13 +21,8 @@ class HiveList(plugins.PluginInterface):
def _generator(self):
for hive in self.list_hives():
try:
FileFullPath = hive.FileFullPath.String
except exceptions.InvalidAddressException:
FileFullPath = ""
yield (0, (format_hints.Hex(hive.vol.offset),
FileFullPath))
hive.name or ""))
def list_hives(self):
"""Lists all the hives in the primary layer"""